Description
A XSS vulnerability was found in module m-server <1.4.2 that allows malicious Javascript code or HTML to be executed, due to the lack of escaping for special characters in folder names.
Remediation
References
https://hackerone.com/reports/319794
Related Vulnerabilities
CVE-2016-10541 Vulnerability in maven package org.webjars.npm:shell-quote
CVE-2021-29445 Vulnerability in npm package jose-node-esm-runtime
CVE-2020-6422 Vulnerability in npm package electron
CVE-2022-21213 Vulnerability in maven package org.webjars.npm:mout
CVE-2016-5005 Vulnerability in maven package org.apache.archiva:archiva